IP Library Granted Patent US 12,587,519
Granted Patent B2
US 12,587,519 · App. 18/669,970 · Granted Mar 24, 2026

Identity access management systems and methods with enforceable compliance

Inventors: Jamie Lin (St. Louis, MO); Sylvan H. Morley, III (Thornton, CO); John Knies (Evansville, ID); Jason Lish (Phoenix, AZ); Vishal Vallabha (Mount Juliet, TN); Glenn Balanoff (Arvada, CO); Christopher Buzzetta (Highlands Ranch, CO); Alexander Tate (Kansas City, MO); Joseph Serrano (Centennial, CO); Mark Howe (Littleton, CO)
Assignee: Level 3 Communications, LLC
H04L63/0807
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,519
App. No.
18/669,970
Granted
Mar 24, 2026
Kind
B2
Abstract

Systems and methods for enforcing compliance-program conformity during authorization-token generation are presented. Applications may be registered with an identity and access management (IAM) system. The registration of the application may include whether the application is subject to one or more compliance program(s). When an authorization token is requested from the IAM system, the IAM system may (a) determine the set of authorization information needed in the token, and (b) determine whether the application is subject to a compliance program. The IAM system may then check an approval source of record to determine whether the user was legitimately approved for the required authorization prior to granting an authorization token. If there is a mismatch between the approval source of record and the authorization information associated with the user identity, then the mismatch may cause certain mitigation actions to be performed.

Claims (72)

1 . An identity and access management system comprising:

at least one processor; and

memory comprising instructions that, when executed by the at least one processor, cause the at least one processor to:

receive a request for an authorization token to authorize at least one function associated with a target application;

determine identity information from the request;

determine authorization information associated with the identity information;

determine that the target application is subject to a compliance program;

determine, based on determining that the target application is subject to the compliance program, whether an approval record associated with the authorization information satisfies the compliance program;

when the approval record is determined to satisfy the compliance program, generate the authorization token according to the authorization information, wherein the authorization token includes an attribute indicating that the approval record satisfies the compliance program; and

transmit the authorization token in response to the request.

2 . The system of claim 1 , wherein the instructions further cause the at least one processor to:

when no approval record is determined to satisfy the compliance program or the approval record is determined to be expired, transmit a request to confirm the authorization information; and

upon receiving confirmation of the authorization information:

generate and store a new approval record;

generate the authorization token according to the authorization information; and

transmit the authorization token in response to the request.

3 . The system of claim 1 , wherein the instructions further cause the at least one processor to:

when no approval record is determined to satisfy the compliance program, transmit a request to confirm the authorization information; and

upon failure to receive confirmation of the authorization information, perform an additional mitigation action, wherein the additional mitigation action comprises one of:

generate an alert;

generate the authorization token according to the authorization information and with an attribute indicating that the approval record is not compliant; or

direct a device making the request to a non-production instance of the target application.

4 . The system of claim 1 , wherein the identity information corresponds to a user, wherein the authorization information includes group membership for the user in a first group, and the approval record comprises a ticketed event by which the user was added to the first group.

5 . The system of claim 4 , wherein determining whether the approval record associated with the authorization information satisfies the compliance program comprises:

determining an expiration time for the approval record based on the compliance program; and

determining whether the approval record has expired for the compliance program.

6 . The system of claim 5 , wherein the instructions further cause the at least one processor to:

determine that the target application is also subject to a second compliance program;

determine a second expiration time for the approval record based on the second compliance program; and

determine whether the approval record has expired for the second compliance program.

7 . The system of claim 1 , wherein the instructions further cause the at least one processor to:

receive a registration request for the target application, including an indication of the compliance program; and

store an association between the target application and the compliance program.

8 . The system of claim 1 , wherein the instructions further cause the at least one processor to:

receive a compliance program profile for the compliance program; and

store an association between the compliance program profile and the target application.

9 . The system of claim 1 , wherein the request for the authorization token is received from a first application, separate from the target application, to use an application programming interface (API) function of the target application.

10 . A method, comprising:

receiving a request for an authorization token to authorize at least one function associated with a target application;

determining identity information from the request;

determining authorization information associated with the identity information;

determining that the target application is subject to a compliance program;

determining, based on determining that the target application is subject to the compliance program, whether an approval record associated with the authorization information satisfies the compliance program;

when the approval record is determined to satisfy the compliance program, generating the authorization token according to the authorization information, wherein the authorization token includes an attribute indicating that the approval record satisfies the compliance program; and

transmitting the authorization token in response to the request.

11 . The method of claim 10 , further comprising:

when no approval record is determined to satisfy the compliance program or the approval record is determined to be expired, transmitting a request to confirm the authorization information; and

upon receiving confirmation of the authorization information:

generating and store a new approval record;

generating the authorization token according to the authorization information; and

transmitting the authorization token in response to the request.

12 . The method of claim 10 , further comprising:

when no approval record is determined to satisfy the compliance program, transmitting a request to confirm the authorization information; and

upon failure to receive confirmation of the authorization information, performing an additional mitigation action, wherein the additional mitigation action comprises one of:

generating an alert;

generating the authorization token according to the authorization information and with an attribute indicating that the approval record is not compliant; or

directing a device making the request to a non-production instance of the target application.

13 . The method of claim 10 , wherein the identity information corresponds to a user, wherein the authorization information includes group membership for the user in a first group, and the approval record comprises a ticketed event by which the user was added to the first group.

14 . The method of claim 13 , wherein determining whether the approval record associated with the authorization information satisfies the compliance program comprises:

determining an expiration time for the approval record based on the compliance program; and

determining whether the approval record has expired for the compliance program.

15 . The method of claim 14 , further comprising:

determining that the target application is also subject to a second compliance program;

determining a second expiration time for the approval record based on the second compliance program; and

determining whether the approval record has expired for the second compliance program.

16 . The method of claim 10 , further comprising:

receiving a registration request for the target application, including an indication of the compliance program; and

storing an association between the target application and the compliance program.

17 . The method of claim 10 , further comprising:

receiving a compliance program profile for the compliance program; and

storing an association between the compliance program profile and the target application.

18 . The method of claim 10 , wherein the request for the authorization token is received from a first application, separate from the target application, to use an application programming interface (API) function of the target application.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2026
From: VALLABHA, VISHAL
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 073841/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2026
From: MORLEY, SYLVAN H., III; TATE, ALEXANDER
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 073456/0547 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2026
From: LIN, JAMIE; LISH, JASON; KNIES, JOHN; BALANOFF, GLENN; BUZZETTA, CHRISTOPHER; SERRANO, JOSEPH; HOWE, MARK
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 073391/0845 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
Continuity (2)
Provisional Application 63503564 · May 22, 2023
Related Publication 20240396884A1 · Nov 28, 2024
References Cited (7)
US 20190098055A1 · Pitre · 2019 [cited by examiner]
US 20200127994A1 · Kukreja · 2020 [cited by applicant]
US 20200153870A1 · Roche · 2020 [cited by applicant]
US 20230075296A1 · Morley · 2023 [cited by applicant]
US 20230132934A1 · Wilson · 2023 [cited by applicant]
US 20230388282A1 · Lin · 2023 [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority, dated Aug. 26, 2024, Int'l Appl. No. PCT/US2024/030338, Int'l Filing Date May 21, 2024; 12 pgs. [cited by applicant]